frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Endpoint State Policy – Policy as Data

https://github.com/scanset/Endpoint-State-Policy
1•scanset•2h ago
Endpoint State Policy (ESP) is a policy-as-data system that keeps policy intent separate from execution.

Policies define desired state and evidence as structured data, not scripts. They’re compiled into constrained contracts that execution engines must follow, producing attestations instead of free-form output.

The contract model limits what execution can do, preventing policy logic from turning into ad-hoc tooling, while allowing the same policy to run across different environments and backends.

ESP focuses on portable intent, constrained execution, and verifiable outcomes — not embedding policy into tools.

Comments

scanset•1h ago
ore context: ESP was built explicitly as a replacement for SCAP/XCCDF-style policy systems, which tightly couple intent, checks, and tooling. That coupling makes reuse, extension, and continuous verification hard.

ESP treats policy as data and compiles it into constrained contracts. Those contracts can be mapped to external frameworks (NIST 800-53/171, CIS, MITRE ATT&CK, etc.) without embedding framework logic into execution. The mapping lives at the policy layer; execution stays generic.

Its strength is in Zero Trust–style architectures: policies define what state is allowed, execution verifies it continuously, and evidence is emitted as attestations rather than one-off reports. That makes it easier to reason about drift, enforcement, and trust boundaries over time.

It’s not a scanner replacement by itself — it’s a substrate for expressing and enforcing policy intent consistently across environments.

Iran developing unconventional warheads for ballistic missiles, sources say

https://www.iranintl.com/en/202512289252
1•mhb•28s ago•0 comments

Scale AI After Meta

https://www.businessinsider.com/pay-cuts-poaching-pivoting-inside-scale-ai-meta-2025-12
1•mancerayder•2m ago•0 comments

Glamorous Christmas: Bringing Charm to Ruby

https://marcoroth.dev/posts/glamorous-christmas
1•todsacerdoti•6m ago•0 comments

Around the General MIDI world in 12 pianos

https://hikari.noyu.me/blog/2025-08-24-around-the-general-midi-world-in-12-pianos.html
1•jrdres•7m ago•0 comments

SmartZip Pro – A powerful archive utility for iPhone and iPad

https://apps.apple.com/us/app/smartzip-pro-zip-rar-7z/id6756837927
1•Pockets•8m ago•1 comments

New Article: Patents and AI

https://idea2patentai.com/articles/provisional-patent-guide-ai
1•idea2patentAI•9m ago•1 comments

39c3: All Sorted by Machines of Loving Grace? [video]

https://media.ccc.de/v/39c3-all-sorted-by-machines-of-loving-grace-ai-cybernetics-and-fascism-and...
1•Klaster_1•10m ago•0 comments

Check and validate JSON-LD structured data on webpages

https://chromewebstore.google.com/detail/json-ld-checker/jdddgiebgdijpopfapkocdnnbgkhddln
1•simonguo•14m ago•1 comments

Big Banks Enjoy Stealth Bailouts

https://www.dcreport.org/2025/12/29/ny-fed-unlimited-cash-infusions-bank-crisis/
2•mindracer•14m ago•0 comments

Reflections on a Year of Prolog and LLMs

https://deepclause.substack.com/p/coming-soon
4•schmuhblaster•16m ago•0 comments

Tech Billionaires Threaten to Flee California–Again

https://www.thenerdreich.com/tech-billionaires-threaten-to-flee-california-again/
4•jethronethro•17m ago•0 comments

Markdown files as React components with live demos

https://rcv-rsuite.vercel.app/quick-start
1•simonguo•17m ago•1 comments

How diamonds are powering a new quantum revolution

https://www.ft.com/content/0b309cd2-aa74-428e-b37b-067665ef17ea
1•freddier•18m ago•0 comments

Justice Department Using Fraud Law to Target Companies on DEI

https://www.wsj.com/politics/policy/trump-doj-dei-fraud-investigations-93213d52
2•KnuthIsGod•19m ago•0 comments

Ask HN: With so many AI models, how do you quickly choose the right one?

1•ankit2098•21m ago•0 comments

AI Video Generation Made Easier with Wan 2.6

https://www.wan26.info/wan/wan-2-6
2•cy1414569•26m ago•1 comments

Why Enterprises Cannot Disclaim Consumer Harm Caused by LLM "Optimization"

https://zenodo.org/records/18091942
2•businessmate•28m ago•0 comments

GPU-Agnostic Programming Using CubeCL

https://www.thomasantony.com/posts/202512281621-gpu-agnostic-programming-using-cubecl/
1•tantony•30m ago•0 comments

America's sweetheart meme came from Philly drill rappers depicting gun violence

https://andrejgee.substack.com/p/6-7-is-another-two-americas-moment
1•panic•37m ago•0 comments

Finding a broken trace on my old Mac with the help of its ROM diagnostics

https://www.downtowndougbrown.com/2025/12/finding-a-broken-trace-on-my-old-mac-with-the-help-of-i...
1•HotGarbage•40m ago•0 comments

'Let them', creatine and fibermaxxing

https://www.theguardian.com/wellness/2025/jul/31/creatine-fibermaxxing-biggest-wellness-trends
2•andsoitis•41m ago•0 comments

ARR is dead. Long live VRR: Vibe Revenue Run-rate

https://gpt3experiments.substack.com/p/arr-is-dead-long-live-vrr
1•nutanc•41m ago•1 comments

Beyoncé is now the fifth billionaire musician

https://www.theguardian.com/us-news/2025/dec/29/beyonce-billionaire-forbes
3•andsoitis•43m ago•0 comments

Show HN: CLI app to control your Mac written in Rust

https://github.com/joonho3020/mac-cli
1•archipelago123•43m ago•0 comments

The Code That Makes Mario Move [video]

https://www.youtube.com/watch?v=ZuKIUjw_tNU
1•handfuloflight•49m ago•0 comments

How Buttondown uses your content to power generative AI

https://buttondown.com/blog/generative-ai
2•nabla9•50m ago•0 comments

Show HN: Cloud Chamber in Browser

https://gist.githack.com/xiupos/a6e6523be4a7772bd43333bbe504bfd0/raw/cloud-chamber.html
2•xiupos•56m ago•0 comments

Show HN: Huntr – An all in one leak checker tool

https://www.huntrfinds.info
1•cloudwaddie•1h ago•1 comments

Meta Buys AI Startup Manus, Adding Paying Users

https://www.wsj.com/tech/ai/meta-buys-ai-startup-manus-adding-millions-of-paying-users-f1dc7ef8
1•LopRabbit•1h ago•0 comments

We Debug Live Kernels Using Drgn – You Can Too

https://blogs.oracle.com/linux/drgn-live-kernel-debug
1•tanelpoder•1h ago•0 comments